iGMS Direct Booking WordPress 插件在 2.0 版本之前,未对其小部件显示设置进行权限验证或转义处理。这使得未认证的用户能够存储任意的 Web 脚本,这些脚本会在管理员查看 iGMS Direct Booking 插件设置时,以及在任何访问者浏览显示该预订小部件的页面时,在浏览器中执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | iGMS Direct Booking | < 2.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | iGMS Direct Booking | 0 ~ 2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88994 | 6.6 MEDIUM | All Bootstrap Blocks 1.3.20 - 1.3.31 - Contributor+ LFI via lightspeed Block Attributes |
| CVE-2026-79713 | 6.5 MEDIUM | Breeze Cache 1.2.5 - 2.5.14 - Unauthenticated Cache Poisoning via Unkeyed Tracking Paramet |
| CVE-2026-90977 | 5.3 MEDIUM | Clean Login < 1.19 - Unauthenticated CAPTCHA Bypass via Empty Session Comparison |
| CVE-2026-86796 | 5.3 MEDIUM | WP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detection and URL Hi |
| CVE-2026-86800 | 5.3 MEDIUM | WP Ghost (Hide My WP Ghost) < 7.0.11 - Unauthenticated URL Hiding Bypass via Loopback Comp |
| CVE-2026-90976 | 5.3 MEDIUM | Clean Login < 1.19 - Unauthenticated Account Creation with Registration Disabled |
| CVE-2026-85350 | UpsellWP < 2.2.10 - Unauthenticated Price Manipulation via Frequently Bought Together | |
| CVE-2026-84902 | King Addons for Elementor < 51.1.81 - Contributor+ Stored XSS via Template Catalog Import | |
| CVE-2026-85127 | VikBooking 1.8.8 - 1.8.14 - Unauthenticated Stored XSS via SVG Chat Attachment | |
| CVE-2026-87767 | WP Shortcut Link <= 1.2.0 - Unauthenticated SQL Injection via url | |
| CVE-2026-85123 | Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Registration Policy Bypass via Login For | |
| CVE-2026-85009 | RestroPress <= 3.4.6 - Unauthenticated Order Enumeration and Order Note Modification via P | |
| CVE-2026-85122 | Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Stored XSS via Form Type Confusion | |
| CVE-2026-84903 | King Addons for Elementor < 51.1.81 - Contributor+ Private Post Content Disclosure via kng | |
| CVE-2026-84904 | King Addons for Elementor 51.1.56 - 51.1.80 - Author+ Missing Authorization via Image Opti | |
| CVE-2026-81810 | All-in-One WP Migration and Backup < 7.111 - Authenticated Privilege Escalation to Admin v | |
| CVE-2026-81340 | MasterStudy LMS < 3.7.50 - Instructor+ Order Status Manipulation via IDOR | |
| CVE-2026-84738 | AF Companion < 2.2.0 - Shop Manager+ Arbitrary File Upload to RCE | |
| CVE-2026-87770 | Price Drop Alert for WooCommerce <= 1.1 - Unauthenticated SQL Injection via product | |
| CVE-2026-87775 | Tz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQLi via tzwrs_update_cell |
Showing top 20 of 32 CVEs. View all on vendor page → →
No comments yet